Project

General

Profile

Actions

Defect #20556

closed

Redirect to HTTPS

Added by Dennis Olsson over 9 years ago. Updated almost 5 years ago.

Status:
Closed
Priority:
Normal
Category:
Website (redmine.org)
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed
Affected version:

Description

http://www.redmine.org/account/register and other sensitive pages should (IMHO) redirect to HTTPS when passwords are involved. Even better would be to redirect all traffic, since session cookies are involved and impersonation is trivial if you are in the right/wrong position/place.

Adding as a defect since HTTPS is configured on the server.


Related issues

Related to Redmine - Feature #25764: Redmine site shoud send emails with HTTPS linksClosed

Actions
Related to Redmine - Defect #32434: Serve redmine.org over httpsClosed

Actions
Actions

Also available in: Atom PDF